< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Kaspersky detects phishing campaign impersonating Zoom and DocuSign

Kaspersky has identified an ongoing phishing campaign that impersonates official communications from Zoom and DocuSign. The attack occurs in waves, utilizing deceptive tactics to steal user credentials and personal information.

The first wave involved fraudulent DocuSign emails sent to corporate addresses across the Middle East, Latin America, Western Europe, Russia, Armenia, and Azerbaijan. These emails contained phishing links designed for credential theft.

A second, more recent wave impersonates Zoom, warning users that their accounts are about to be deactivated. This phase employs two primary methods: phishing links that redirect victims to fraudulent pages, and embedded forms used to collect personal data and credit card information. As of September 11, over one thousand phishing emails related to this campaign have been detected.

Entities

DocuSign · Kaspersky · Zoom